commit-push-pr-flow

Pass

Audited by Gen Agent Trust Hub on Feb 20, 2026

Risk Level: SAFE
Full Analysis
  • [Prompt Injection] (SAFE): The instructions specify a clear workflow for git operations and do not attempt to bypass safety filters or extract system prompts.
  • [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials or unauthorized data exfiltration attempts were found. The skill relies on the user's existing GitHub CLI configuration.
  • [Remote Code Execution] (SAFE): The skill does not download or execute remote scripts or external packages.
  • [Indirect Prompt Injection] (SAFE): While the skill processes the results of previous tasks, it does not demonstrate specific interpolation vulnerabilities or unsafe handling of untrusted data beyond its primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 20, 2026, 07:35 PM